Summary & highlights
NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Framework. ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs. ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin).
Highlights
- TL-2026-1582 — TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East Governments
- TL-2026-1584 — Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA
- TL-2026-1585 — "LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive Hijacking
- TL-2026-1588 — Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential Recovery
- TL-2026-1589 — SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)
Theme of the day
Routine activity — no dominant theme emerged.
- credential-theft
- detection-engineering
- data-exfiltration
- cisa-kev
- anti-analysis
Threats published
24 threat lines in the 2026-07-21 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Zimbra Collaboration Suite 10.1.20 Patches Critical Unauthenticated SNMP/Swatchdog Command Injection Plus Six Additional CVEsCRITICAL
- Gitea CVE-2026-58443: Authorization Bypass in Pull Request Update API Enables Private Repo AccessCRITICAL
- Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop ExploitationCRITICAL
- Fastjson 1.2.x Gadget-Free Remote Code Execution via @JSONType Remote Class Load (Versions 1.2.68-1.2.83)CRITICAL
- Palo Alto Networks PAN-OS / Prisma Access GlobalProtect Authentication Bypass (CVE-2026-0257) — Active Exploitation, CISA KEV (update)CRITICAL
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) (update)CRITICAL
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155) (update)CRITICAL
- TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East GovernmentsHIGH
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFAHIGH
- "LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive HijackingHIGH
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential RecoveryHIGH
- SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)HIGH
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational InstitutionsHIGH
- FakeGit Campaign: 7,600 Malicious GitHub Repos Push SmartLoader and StealC Malware via AI Tool Poisoning (Water Kurita)HIGH
- Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power GridsHIGH
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern Manticore / Iran MOIS-Nexus)HIGH
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence) (update)HIGH
- Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053) (update)HIGH
- NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack FrameworkMEDIUM
- ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate ProgramsMEDIUM
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin)MEDIUM
- Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive Threats Across IoT/OT/IoMT InfrastructureMEDIUM
- Executive Order: Defense Contractors Ordered to Map Software Suppliers Across Critical Supply Chains ("Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials")
- Capital One Open-Sources VulnHunter: Agentic, Claude-Opus-4.8-Powered Vulnerability Detection and Remediation Tool
Techniques observed
222 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1005
- T1008
- T1010
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.003
- T1021.005
- T1021.006
- T1025
- T1027
- T1027.003
- T1027.004
- T1027.006
- T1033
- T1036
- T1036.002
- T1036.003
- T1036.005
- T1036.007
- T1039
- T1041
- T1046
- T1047
- T1048
- T1049
- T1052
- T1053
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.005
- T1059.007
- T1068
- T1069
- T1069.002
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1074.001
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1090.004
- T1095
- T1098
- T1098.001
- T1098.003
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1114.003
- T1115
- T1119
- T1129
- T1132
- T1133
- T1134
- T1135
- T1136
- T1140
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1195.003
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1213
- T1213.003
- T1217
- T1218
- T1218.009
- T1219
- T1222
- T1482
- T1485
- T1486
- T1489
- T1490
- T1491.002
- T1495
- T1496
- T1497
- T1498
- T1499
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1531
- T1534
- T1537
- T1538
- T1539
- T1546
- T1547
- T1547.001
- T1547.013
- T1548
- T1548.002
- T1550
- T1550.001
- T1550.002
- T1550.003
- T1550.004
- T1552
- T1552.001
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1555.004
- T1556
- T1556.006
- T1557
- T1560
- T1560.001
- T1562
- T1562.001
- T1564
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1568.003
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.001
- T1585
- T1585.001
- T1585.002
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589.002
- T1590
- T1591
- T1591.002
- T1592
- T1592.002
- T1593
- T1595
- T1595.002
- T1596
- T1596.005
- T1598
- T1606
- T1609
- T1610
- T1611
- T1613
- T1620
- T1621
- T1650
- T1656
- T1657
Threat actors
8 named threat actors across the reports.
- ReHub Forum Operators
- LAPSUS
- APT34
- Water Kurita
- Cavern Manticore
- Cl0p
- Qilin / Agenda RaaS affiliates
- JADEPUFFER
Nation-state attribution
- Russia
- China, Russia, Iran
- Iran
Threat categories
- MALWARE
- THREAT_ACTOR
- CAMPAIGN
- THREAT_INTEL
- SUPPLY_CHAIN
- PHISHING
- VULNERABILITY
- DATA_BREACH
- RANSOMWARE
Severity breakdown
- critical7
- high11
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 145
- behavioral 144
- network 144
- entity 76
- infrastructure 58
- tool 49
- malware 42
- technique 25
- package 14
- vulnerability 13